PYSEC-2026-2033

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/weasyprint/PYSEC-2026-2033.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-2033
Aliases
Published
2026-07-07T11:45:34.890224Z
Modified
2026-07-07T17:46:23.962040206Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
Summary
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
Details

Impact

Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs.

Patches

Fixed by 734ee8e that’s included in 61.2

Workarounds

  • Check that no PDF attachment is defined in source HTML.
  • Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.
References

Affected packages

PyPI / weasyprint

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
61.0
Fixed
61.2

Affected versions

61.*
61.0
61.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/weasyprint/PYSEC-2026-2033.yaml"